This response says absolutely nothing about how the vulnerability is prevented in the future. It's just a bunch of vague promises and mumbo jumbo. What specific procedures are in place to prevent it? At a minimum, I expect to see something specific like when you guys almost lost your domain because of Gandi [1].
And even then, can I have an option to select absolutely no human intervention possible? Having any human intervention is simply not acceptable.
I already have multiple ways of recovering my account, and I never, ever want human assistance on this. I use a password manager, and I will never, ever need FastMail assistance on login.
[1]: https://blog.fastmail.com/2014/04/10/when-two-factor-authent...